Executive brief
Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to access sensitive information. To exploit this, an attacker would typically need to trick a user into opening a specially crafted Excel file. Successful exploitation could lead to the unauthorized disclosure of data or cause the application to crash, potentially disrupting business operations.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Excel and Office products. The flaw is triggered when the application fails to properly validate input while reading from a memory buffer, which can be exploited by an attacker who convinces a user to open a malicious file. While the primary impact is local information disclosure, the CVSS vector also indicates a high impact on availability, suggesting the flaw may cause application instability or crashes. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
- Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
- Microsoft Microsoft Office 2019 versions prior to July 2026 updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
- Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
- Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
- Microsoft Office Online Server versions prior to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory